Skip to content

Phishing

Phishing is a message that impersonates a trusted organization in order to capture your credentials. Its legal significance is that credentials are an "access device", so a transfer the thief then makes is unauthorized under federal rules.

Last reviewed by Steven Fox, CFP®, EA on

Quick Summary

  • It is a credential-capture technique. The message's purpose is to obtain a password, a code or a card number, not usually to be paid directly.
  • Federal rules treat a password or code as an "access device", the same category as a debit card.
  • Handing over credentials to a phisher does not make the resulting transfer authorized. The regulator's official interpretation says a device obtained through fraud yields an unauthorized transfer.
  • A payment you are persuaded to send yourself is a different case, and the electronic-transfer protections do not reach it.
  • It was the most reported crime type to the FBI's complaint center in 2025 by complaint count, with 191,561 complaints of phishing and spoofing.

Definition

Phishing is the use of a message that impersonates a trusted organization in order to obtain something the sender is not entitled to, most often login credentials, a one-time code, a card number or a Social Security number. The Internet Crime Complaint Center defines it as "the use of unsolicited email, text messages, and telephone calls purportedly from a legitimate company requesting personal, financial, and/or login credentials." No statute defines the word, which is worth knowing because the legally operative question is never "was this phishing" but what happened to the credentials afterwards.

Two variants have their own names and the same structure: the text-message version and the voice-call version, sometimes called smishing and vishing respectively. Phishing is also frequently paired with spoofing, which is the falsification of the sender's identity, address or caller ID that makes the impersonation credible. The distinction between the technique and the resulting loss matters: phishing itself rarely takes money. It takes the means of access, and the money moves afterwards.

Advanced Explanation

The regulatory fact worth carrying, because it is a right and most people do not know they have it. Regulation E, the federal rule governing consumer electronic fund transfers, defines an access device at 12 CFR 1005.2(a)(1) as "a card, code, or other means of access to a consumer's account, or any combination thereof, that may be used by the consumer to initiate electronic fund transfers." A password, a PIN and a one-time code are all access devices, in exactly the same category as the plastic card.

Then 1005.2(m) defines an "unauthorized electronic fund transfer" as one "initiated by a person other than the consumer without actual authority to initiate the transfer and from which the consumer receives no benefit", and excludes from that definition a transfer initiated "(1) By a person who was furnished the access device ... by the consumer, unless the consumer has notified the financial institution that transfers by that person are no longer authorized." Read alone, that carve-out looks fatal for a phishing victim, because they did hand the credentials over.

The official interpretation closes the gap in one sentence. Supplement I to part 1005, comment 2(m)-3, is headed "Access device obtained through robbery or fraud" and reads: "An unauthorized EFT includes a transfer initiated by a person who obtained the access device from the consumer through fraud or robbery." So being tricked out of your credentials is not the same as furnishing them, and the transfer the phisher then makes is unauthorized. The comparison the commentary draws is with comment 2(m)-2, which covers a consumer who "furnishes an access device and grants authority to make transfers to a person (such as a family member or co-worker) who exceeds the authority given", and says that consumer "is fully liable". Granting authority to someone who abuses it is the consumer's problem. Being deceived out of a code is not.

The line this sits on, and the side of it that gives nothing. The whole distinction turns on who initiated the transfer, not on whether the consumer was deceived. Comment 2(m)-3 is about a transfer the thief makes. A transfer the consumer is talked into making themselves is initiated by the consumer and is therefore authorized, however complete the deception, and Regulation E's list of what counts as an "error" contains no limb for inducement. The only comment treating a consumer's own transfer as unauthorized is 2(m)-4, and its trigger is physical force: "An EFT at an ATM is an unauthorized transfer if the consumer has been induced by force to initiate the transfer." So the practical rule is that being deceived into revealing credentials is generally covered, and being deceived into sending the money yourself generally is not. That is the boundary between this page and the pages on fraud and on wire transfers, and it is the single most consequential thing to get right in this area.

The three things a phishing message is trying to do, which is a more useful taxonomy than the channel it arrives on. The first is credential harvesting: a link to a convincing copy of a login page, so the credentials are typed into the wrong site. Where two-factor authentication is in place, the same page will ask for the code, and a real-time operator will use it within its validity window, which is why supplying a code to anyone who asked for it is the point where the account is lost. The second is malware delivery: an attachment or download that installs software able to capture what is typed. The third is payment redirection: no credentials at all, just an instruction to pay a real invoice to a different account, which is the form the closing-table version of the scheme takes.

Only the first two lead to the access-device analysis above. The third produces a payment the consumer made themselves, which is the unprotected side of the line.

Scale, dated and attributed. In the FBI's 2025 Internet Crime Report, phishing and spoofing together were the most frequently reported crime type, with 191,561 complaints, against reported losses of $215,843,126. The comparison worth drawing is with the loss figures for other categories: measured by money, phishing is far from the largest, because it is usually the first step rather than the loss itself. The dollars end up counted under whatever the credentials were then used for.

How to Remember

Phishing takes the key, not the money. Federal rules treat your password as a device like your debit card, and a device taken by trickery is a device stolen, not a device lent.

Used in a Sentence

“The message came from an address one character off her bank's and asked her to confirm a code, which is phishing rather than a security check.”

How It Works

A message arrives that appears to come from a bank, an employer, a government agency or a service the recipient uses. It supplies a reason to act now and a link or a number. The recipient enters credentials on a page that looks correct, or reads out a code. The credentials are used immediately, often within minutes, because a one-time code has a short life. Money then leaves by whatever route the compromised account supports.

A hypothetical example of how one incident splits across the authorized line, because the two halves have different answers. Amina receives a text apparently from her bank about a suspicious payment. She follows the link, enters her online banking credentials on the fake page, and reads out the code that arrives.

Within the hour the operator uses those credentials to move $2,100 out of her checking account in two transfers. Then the operator calls her, claiming to be the bank's fraud team, and persuades her to move a further $2,800 herself to what she is told is a protected account. The total loss is $4,900 ($2,100 plus $2,800).

The two halves are legally different. The $2,100 was initiated by someone other than Amina, using an access device obtained from her through fraud, so comment 2(m)-3 makes it an unauthorized electronic fund transfer and her liability is limited by Regulation E's tiers, which depend on how quickly she reports after learning of the loss. The $2,800 she initiated herself. It was authorized, however thoroughly she was deceived, and Regulation E's definition of an error has no limb for a payment induced by deception, so nothing in that rule requires the bank to return it.

So a single incident can be $2,100 of protected loss and $2,800 of unprotected loss, and the dividing line is not how badly she was wronged. It is whose hand was on the transfer. Report both immediately anyway, because the bank still owes an investigation on the asserted error, and because a payment that has not yet settled can sometimes still be stopped.

Pros and Cons

Phishing has no upside, so what follows is what protects a household and what the protections do not reach.

What genuinely reduces exposure

  • Treating any request for a one-time code as the end of the conversation. No legitimate institution needs a code read back to it, and supplying one is the moment the account is lost.
  • Reaching the institution on a number or address you already had, rather than one supplied in the message, which defeats the impersonation regardless of how good it is.
  • Knowing that credentials taken by deception are treated as a stolen access device rather than a lent one, so a transfer the thief makes is unauthorized.
  • Reporting quickly, because the liability tiers for an unauthorized transfer turn on how soon the loss is reported after it is learned of.

What the protections do not reach

  • A payment you were persuaded to send yourself. It is authorized, and the electronic-transfer error rules contain no limb for inducement.
  • A domestic wire and a paper check, which sit outside the electronic-transfer consumer procedures altogether.
  • Cryptocurrency transfers, gift card codes and cash, which have no reversal mechanism whoever authorized them.
  • Credentials already reused elsewhere, since the same password captured once will be tried against every other account.
  • Anything the credentials revealed about you rather than moved for you, which is a different harm with a different remedy set.

People Also Asked

Answers to the most frequently asked questions.

If I gave a scammer my password, am I liable for what they took?
Not simply because you handed it over. Regulation E treats a code or password as an "access device" under 12 CFR 1005.2(a)(1), and the official interpretation at Supplement I comment 2(m)-3 says that an unauthorized transfer "includes a transfer initiated by a person who obtained the access device from the consumer through fraud or robbery." So the carve-out for a device you furnished to someone does not reach a device obtained by deception, and your liability for what the thief moves is limited by the regulation's tiers, which depend on how quickly you report after learning of the loss.
What if the scammer talked me into sending the money myself?
That case is treated differently, and the difference is the most important thing to know here. Regulation E turns on who initiated the transfer, not on whether you were deceived, so a payment you made yourself is authorized however complete the deception. The rule's definition of an error has no limb for inducement, and the only official comment treating your own transfer as unauthorized involves physical force. Report it immediately regardless, because the bank still owes you an investigation of an asserted error and an unsettled payment can sometimes be stopped.
What is the difference between phishing, smishing and vishing?
Only the channel. Phishing is the general term and is usually associated with email; smishing describes the text-message version and vishing the voice-call version. The structure and the countermeasure are identical in all three: an impersonated organization, a reason to act now, and a request for credentials or a code. Spoofing is a related but distinct thing, meaning the falsification of the sender's address or caller ID that makes any of them look genuine.
Does two-factor authentication stop phishing?
It raises the cost of an attack without closing it, because the same fake page that captures a password can ask for the code, and an operator working in real time can use it inside its validity window. What actually defeats the attempt is refusing to supply a code to anyone who asked for it, whatever they claim to be verifying, and reaching the institution independently to check. Treat the arrival of a code you did not request as evidence that someone already has your password.
How common is phishing?
By complaint count it was the largest category reported to the FBI's Internet Crime Complaint Center in 2025: phishing and spoofing together accounted for 191,561 complaints, against reported losses of $215,843,126. By money it sits well down the list, and that gap is the point. Phishing is usually the first step rather than the loss, so the dollars are counted under whatever the stolen credentials were then used to do.

Have a question a definition can't answer?

Advice-only advisors answer questions like this for a transparent flat fee — no products, no commissions, no asset management.

Find an Advisor